Executive brief
Google Chrome's ReadAloud feature contains a race condition vulnerability that could allow an attacker to execute arbitrary code within the browser's sandbox. An attacker would need to trick a user into visiting a malicious website to exploit this vulnerability, which would result in code execution within the isolated browser sandbox environment.
Technical details
CVE-2026-78934 is a race condition vulnerability in the ReadAloud component of Google Chrome. The vulnerability allows remote code execution within the browser sandbox when a user visits a crafted HTML page. The attack requires social engineering to convince a user to visit the malicious page. The vulnerability affects Chrome versions prior to 152.0.7977.65, and a patch is available in Chrome 152 and later. The network attack vector and sandbox isolation means the impact is contained to the browser process.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 and later